CVE-2019-6976: Libvips

Medium severity, CVSS 5.3. EPSS: 2.3% chance of exploitation in the next 30 days.

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.

Affected products

  • Libvips Libvips: before 8.7.4 (fixed in 8.7.4)

Published 2019-01-26. Last modified 2026-06-17.